AI agent hacks gym booking system without user request
An AI agent performing a routine booking task autonomously exploited vulnerabilities in a gym's software. It secured spots on blocked dates and removed other members from the waitlist without the user's input.

In the last month, the AI sector has begun to face a new reality, in which the capabilities of advanced and experimental AI models are so powerful that they are able to escape their closed test environments and hack into sites and services on the open internet. OpenAI, Anthropic, and Meta have all faced this problem, but an incident that occurred in Australia clarifies that the risk posed by AI models is no longer limited to controlled testing, but is a daily reality for us all.
This follows an incident where an AI agent, while performing a routine task for its user, hacked into a gym's computer systems. According to a report by the Australian network ABC, a user named Andrew asked his custom-built AI agent on the OpenClay platform to book him a spot in a morning class. Without Andrew asking, the agent exposed a vulnerability in the booking management software and found a way to reserve spots months in advance, on dates that were still blocked by the gym. Furthermore, the agent discovered how to remove a member from the waiting list who was in a higher position than Andrew—all without any explicit instruction.
The incident is significant because it does not involve models under extreme testing scenarios, but rather a model in daily use. The agent was not instructed to perform complex actions or test cyberattack capabilities; it was sent to perform a routine task and, along the way, exploited vulnerabilities in an online system.
"The autonomy of AI agents creates opportunities for systems to choose methods that users did not expect," Bill Simpson-Young, founder and CEO of the Gradient Institute, told ABC. "Someone might ask an agent to do something quite innocent, but on the way to completing the task, the agent might perform activities that the human did not consider or explicitly request. We have built a complex world on the internet that is operated by software, but software has holes. Now we are adding highly skilled AI agents that can act at scale and speed, and the whole model just breaks."
This is the optimistic scenario, where agents act contrary to user intentions. The availability of these capabilities in agents accessible to users with minimal knowledge also allows bad actors to use them for targeted cyberattacks. It is likely that this is already happening on a growing scale, and the revelations of the past month clarify that we live in a new world where AI agents roam the internet and penetrate online services with ease.





